Andriller – is software utility with a collection of forensic tools for smartphones. It performs read-only, forensically sound, non-destructive acquisition from Android devices.
It has features, such as powerful Lockscreen cracking for Pattern, PIN code, or Password; custom decoders for Apps data from Android (some Apple iOS & Windows) databases for decoding communications.
Extraction and decoders produce reports in HTML and Excel formats.
It is highly advised to setup a virtual environment to install Andriller and its dependencies in it. However, it is not essential, and the global environment can also be used. Depending on how Python was setup, it may be needed to substitute python and pip to python3 and pip3 retrospectively for the instructions below.
Windows only: when installing Python from, make sure Add Python to PATH is ticked.
adbpython3-tk[Ubuntu/Debian] Install from Terminal:
sudo apt-get install android-tools-adb python3-tk [Mac] Install from Homebrew:
brew install android-platform-tools [Windows] : Included.
Create a virtual environment using Python 3:
python3 -m venv env Activate the virtual environment (Linux/Mac):
source env/bin/activate Activate the virtual environment (Windows):
.\env\Scripts\activate Install Andriller with its Python dependencies (same command to upgrade it):
pip install andriller -U python -m andriller The groupdel command in Linux removes a group from the system. It deletes the group's entry from /etc/group and /etc/gshadow,…
The wc command in Linux counts lines, words, characters, and bytes in files or standard input. It…
The top command in Linux provides a real-time view of running processes and system resource usage. From…
The usermod command in Linux modifies existing user account attributes. You can use it to manage group…
The sort command in Linux reads lines from files or standard input and writes them to standard…
The wall command in Linux sends a message to the terminals of all currently logged-in users. The…